# Geo\_point error in visualization

**URL:** <https://discuss.elastic.co/t/geo-point-error-in-visualization/119352>\
**Category:** Kibana\
**Created:** [February 11, 2018, 12:32am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352 "2018-02-11T00:32:00Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [February 11, 2018, 12:32am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/1 "2018-02-11T00:32:00Z")

</div>

Hi,

Using ELK stack 6.2.0

For weblogs getting -

**Index pattern does not contain any of the following field types: geo\_point**

error in Kibana while creating the Visualize -\> Map -\> Coordinate Map

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/1/71bdbe7f52e51307e2ae55c263508d1a1380e96e.jpg)

This is how logstash config file looks -

```
input {

   file {
     type => "weblog"
     path => "C:/elklogs/access_log.txt"
     start_position => "beginning"
     ignore_older => 0
   }
}

filter {

    if [type] == "weblog" {

        grok {
           patterns_dir => ".\patterns"
           match => { "message" => ["%{IBMACCESSLOG2}", "%{IBMACCESSLOG3}"] }
        }
        date {
          match => ["timestamp", "[dd/MMM/yyyy:HH:mm:ss Z]" ]
        }
        geoip {
            source => "clientip"
			target => "geoip"
        }
        useragent {
            source => "weblog_agent"
        }
        if "_grokparsefailure" not in [tags] {
            mutate {
                 remove_field => ["message"]
            }
        }		
    }

}

output {
   
     elasticsearch {
        action => "index"
        hosts => "localhost:9200"
        index => "sunview-%{+YYYY.MM}"
     }
     stdout {
        codec => rubydebug
     }	
}

```

logstash's rubydebug does show all the fields of **geoip**

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/6/266d8618954a21c45255720d2652667dbefc5e4c.png)

Similarly, the index pattern fields screen from Kibana shows geoip fields minus geo\_point

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0ef0080feb2281891de77be0a9c3efb35c7ea202.png)

Please help on how to get geo\_point correctly.

Thank you!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 11, 2018, 11:31pm UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/2 "2018-02-11T23:31:13Z")

</div>

It's because it's `geoip.location.lat` and `geoip.location.lon`, when it should be an array of just two numbers under `geoip.location`.

Is that the only config you had?

---

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [February 12, 2018, 2:45am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/3 "2018-02-12T02:45:24Z")

</div>

Thanks for looking.

There are other logs/config but none of them have IP data in it. Will that impact weblogs?

This is how the template data looks (using the default) -

**GET /\_template/logstash**

```
{
  "logstash": {
    "order": 0,
    "version": 60001,
    "index_patterns": [
      "logstash-*"
    ],
    "settings": {
      "index": {
        "refresh_interval": "5s"
      }
    },
    "mappings": {
      "_default_": {
        "dynamic_templates": [
          {
            "message_field": {
              "path_match": "message",
              "match_mapping_type": "string",
              "mapping": {
                "type": "text",
                "norms": false
              }
            }
          },
          {
            "string_fields": {
              "match": "*",
              "match_mapping_type": "string",
              "mapping": {
                "type": "text",
                "norms": false,
                "fields": {
                  "keyword": {
                    "type": "keyword",
                    "ignore_above": 256
                  }
                }
              }
            }
          }
        ],
        "properties": {
          "@timestamp": {
            "type": "date"
          },
          "@version": {
            "type": "keyword"
          },
          "geoip": {
            "dynamic": true,
            "properties": {
              "ip": {
                "type": "ip"
              },
              "location": {
                "type": "geo_point"
              },
              "latitude": {
                "type": "half_float"
              },
              "longitude": {
                "type": "half_float"
              }
            }
          }
        }
      }
    },
    "aliases": {}
  }
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 12, 2018, 3:22am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/4 "2018-02-12T03:22:51Z")

</div>

Is that the default one?

---

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [February 12, 2018, 3:57am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/5 "2018-02-12T03:57:19Z")

</div>

The config is not using any template so I believe that's the default one. Logstash logs showing logstash installing the template in ES -

```
[2018-02-10T19:10:49,193][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es_version=>nil}
[2018-02-10T19:10:49,202][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document _type {:es_version=>6}
[2018-02-10T19:10:49,222][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=>nil}
[2018-02-10T19:10:49,249][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage_template=>{"template"=>"logstash-*", "version"=>60001, "settings"=>{"index.refresh_interval"=>"5s"}, "mappings"=>{"_default_"=>{"dynamic_templates"=>[{"message_field"=>{"path_match"=>"message", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false}}}, {"string_fields"=>{"match"=>"*", "match_mapping_type"=>"string", "mapping"=>{"type"=>"text", "norms"=>false, "fields"=>{"keyword"=>{"type"=>"keyword", "ignore_above"=>256}}}}}], "properties"=>{"@timestamp"=>{"type"=>"date"}, "@version"=>{"type"=>"keyword"}, "geoip"=>{"dynamic"=>true, "properties"=>{"ip"=>{"type"=>"ip"}, "location"=>{"type"=>"geo_point"}, "latitude"=>{"type"=>"half_float"}, "longitude"=>{"type"=>"half_float"}}}}}}}}
[2018-02-10T19:10:49,302][INFO][logstash.outputs.elasticsearch] Installing elasticsearch template to _template/logstash
[2018-02-10T19:10:49,472][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=>"LogStash::Outputs::ElasticSearch", :hosts=>["//localhost:9200"]}
[2018-02-10T19:10:49,968][INFO][logstash.filters.geoip] Using geoip database {:path=>"C:/tools/ELK620/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-geoip-5.0.3-java/vendor/GeoLite2-City.mmdb"}
```

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [February 12, 2018, 6:15am UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/6 "2018-02-12T06:15:04Z")

</div>

Hi @ggajanan,

Try This Template it may be worked.

After Change the template delete the old Index

Save this template in your logstash bin folder and give the path in your logstash config file like

template =\> "/usr/share/logstash/bin/template.json"  
template\_name =\> "test-\*"

template.json  
{  
"template" : "test-_",  
"version" : 50001,  
"settings" : {  
"index.refresh\_interval" : "5s"  
},  
"mappings" : {  
"default" : {  
"\_all" : {"enabled" : true, "omit\_norms" : false},  
"dynamic\_templates" : [ {  
"message\_field" : {  
"path\_match" : "message",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text",  
"omit\_norms" : false  
}  
}  
}, {  
"string\_fields" : {  
"match" : "_",  
"match\_mapping\_type" : "string",  
"mapping" : {  
"type" : "text", "omit\_norms" : false,  
"fields" : {  
"keyword" : { "type": "keyword", "ignore\_above": 256 }  
}  
}  
}  
} ],  
"properties" : {  
"@timestamp": { "type": "date", "include\_in\_all": false },  
"@version": { "type": "keyword", "include\_in\_all": false },  
"geoip" : {  
"dynamic": true,  
"properties" : {  
"ip": { "type": "ip" },  
"location" : { "type" : "geo\_point" },  
"latitude" : { "type" : "half\_float" },  
"longitude" : { "type" : "half\_float" }  
}  
},  
"location": { "type": "geo\_point" }  
}  
}  
}  
}

Thanks & Reagrds,  
Krunal.

---

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [February 12, 2018, 11:37pm UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/7 "2018-02-12T23:37:11Z")

</div>

Hi Krunal,

I had to make some changes to install it in 6.2 and installed it in ES using Kibana console -

```
PUT _template/weblog.template
{
  "index_patterns": ["weblog*"],
  "settings": {
    "number_of_shards": 1,
    "index.refresh_interval": "5s"
  },
	"mappings": {
		"default": {
			"dynamic_templates": [
				{
					"message_field": {
						"path_match": "message",
						"match_mapping_type": "string",
						"mapping": {
							"type": "text",
							"omit_norms": false
						}
					}
				},
				{
					"string_fields": {
						"match": "",
						"match_mapping_type": "string",
						"mapping": {
							"type": "text",
							"omit_norms": false,
							"fields": {
								"keyword": {
									"type": "keyword",
									"ignore_above": 256
								}
							}
						}
					}
				}
			],
			"properties": {
				"@timestamp": {
					"type": "date"
				},
				"@version": {
					"type": "keyword"
				},
				"geoip": {
					"dynamic": true,
					"properties": {
						"ip": {
							"type": "ip"
						},
						"location": {
							"type": "geo_point"
						},
						"latitude": {
							"type": "half_float"
						},
						"longitude": {
							"type": "half_float"
						}
					}
				},
				"location": {
					"type": "geo_point"
				}
			}
		}
	}
}

```

Modified o/p of logstash config to make use of this template -

```
output {
   
     elasticsearch {
        action => "index"
        hosts => "localhost:9200"
        index => "weblog-%{+YYYY.MM}"
		template_name => "weblog.template"
     }
     stdout {
        codec => rubydebug
     }	
}

```

Now hitting following error -

```
[2018-02-12T18:23:04,534][INFO][logstash.pipeline] Pipeline started succesfully {:pipeline_id=>"main", :thread=>"#<Thread:0x76158012 sleep>"}
[2018-02-12T18:23:04,561][INFO][logstash.agent] Pipelines running {:count=>1, :pipelines=>["main"]}
[2018-02-12T18:23:06,113][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"weblog-2018.02", :_type=>"doc", :_routi
ng=>nil}, #<LogStash::Event:0x770eb729>], :response=>{"index"=>{"_index"=>"weblog-2018.02", "_type"=>"doc", "_id"=>"1R5UjGEBVbzVFun6OmAG", "status"=>400, "error"=>{"type"=>"illegal_argument_exception"
, "reason"=>"[geoip.location] is defined as an object in mapping [doc] but this name is already used for a field in other types"}}}}
[2018-02-12T18:23:06,115][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"weblog-2018.02", :_type=>"doc", :_routi
ng=>nil}, #<LogStash::Event:0x74961af6>], :response=>{"index"=>{"_index"=>"weblog-2018.02", "_type"=>"doc", "_id"=>"4R5UjGEBVbzVFun6OmAH", "status"=>400, "error"=>{"type"=>"illegal_argument_exception"
, "reason"=>"[geoip.location] is defined as an object in mapping [doc] but this name is already used for a field in other types"}}}}
[2018-02-12T18:23:06,114][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"weblog-2018.02", :_type=>"doc", :_routi
ng=>nil}, #<LogStash::Event:0x3def49fe>], :response=>{"index"=>{"_index"=>"weblog-2018.02", "_type"=>"doc", "_id"=>"yR5UjGEBVbzVFun6OmAF", "status"=>400, "error"=>{"type"=>"illegal_argument_exception"
, "reason"=>"[geoip.location] is defined as an object in mapping [doc] but this name is already used for a field in other types"}}}}

```

This used to work perfectly on ELK stack 5.3.0 for. Not sure what's wrong here and stuck on this. Any help is really appreciated.

Thank you!

---

<div class="post-metadata">

**Author:** ![ggajanan](https://avatars.discourse-cdn.com/v4/letter/g/838e76/32.png) [@ggajanan](https://discuss.elastic.co/u/ggajanan)\
**Post date:** [February 13, 2018, 1:32pm UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/8 "2018-02-13T13:32:18Z")

</div>

@warkolmHi, can you please look into this?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 13, 2018, 1:32pm UTC](https://discuss.elastic.co/t/geo-point-error-in-visualization/119352/9 "2018-03-13T13:32:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
